Ladder versions 001 through 0021 fail to apply sufficient default restrictions on destination addresses, allowing an attacker to make GET requests to addresses that would typically not be accessible from an external context An attacker can access private address ranges, locally listening services, and cloud instance metadata APIs ...